CVE-2023-5764

A template injection flaw was found in Ansible where a user's controller internal templating operations may remove the unsafe designation from template data. This issue could allow an attacker to use a specially crafted file to introduce templating injection when supplying templating data.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:redhat:ansible:*:*:*:*:*:*:*:*
cpe:2.3:a:redhat:ansible:*:*:*:*:*:*:*:*
cpe:2.3:a:redhat:ansible:2.16.0:-:*:*:*:*:*:*
cpe:2.3:a:redhat:ansible:2.16.0:beta1:*:*:*:*:*:*
cpe:2.3:a:redhat:ansible:2.16.0:beta2:*:*:*:*:*:*
cpe:2.3:a:redhat:ansible:2.16.0:rc1:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:a:fedoraproject:extra_packages_for_enterprise_linux:8.0:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:38:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:39:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
OR cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:*
OR cpe:2.3:a:redhat:ansible_automation_platform:2.4:*:*:*:*:*:*:*
cpe:2.3:a:redhat:ansible_developer:1.1:*:*:*:*:*:*:*
cpe:2.3:a:redhat:ansible_inside:1.2:*:*:*:*:*:*:*

History

16 Sep 2024, 17:16

Type Values Removed Values Added
References
  • {'url': 'https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/X7Q6CHPVCHMZS5M7V22GOKFSXZAQ24EU/', 'tags': ['Third Party Advisory'], 'source': 'secalert@redhat.com'}

25 Apr 2024, 16:15

Type Values Removed Values Added
Summary (en) A template injection flaw was found in Ansible where a user's controller internal templating operations may remove the unsafe designation from template data. This issue could allow an attacker to use a specially crafted file to introduce code injection when supplying templating data. (en) A template injection flaw was found in Ansible where a user's controller internal templating operations may remove the unsafe designation from template data. This issue could allow an attacker to use a specially crafted file to introduce templating injection when supplying templating data.

20 Dec 2023, 17:35

Type Values Removed Values Added
First Time Redhat ansible Developer
Redhat ansible Inside
Fedoraproject fedora
Fedoraproject
Redhat enterprise Linux
Redhat ansible
Redhat ansible Automation Platform
Redhat
Fedoraproject extra Packages For Enterprise Linux
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.8
CWE NVD-CWE-Other
CPE cpe:2.3:a:redhat:ansible:2.16.0:-:*:*:*:*:*:*
cpe:2.3:a:redhat:ansible:*:*:*:*:*:*:*:*
cpe:2.3:a:redhat:ansible:2.16.0:rc1:*:*:*:*:*:*
cpe:2.3:a:redhat:ansible:2.16.0:beta1:*:*:*:*:*:*
cpe:2.3:a:redhat:ansible:2.16.0:beta2:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:38:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:39:*:*:*:*:*:*:*
cpe:2.3:a:fedoraproject:extra_packages_for_enterprise_linux:8.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*
cpe:2.3:a:redhat:ansible_inside:1.2:*:*:*:*:*:*:*
cpe:2.3:a:redhat:ansible_developer:1.1:*:*:*:*:*:*:*
cpe:2.3:a:redhat:ansible_automation_platform:2.4:*:*:*:*:*:*:*
References
  • () https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/X7Q6CHPVCHMZS5M7V22GOKFSXZAQ24EU/ - Third Party Advisory
References () https://bugzilla.redhat.com/show_bug.cgi?id=2247629 - () https://bugzilla.redhat.com/show_bug.cgi?id=2247629 - Issue Tracking, Patch, Vendor Advisory
References () https://access.redhat.com/security/cve/CVE-2023-5764 - () https://access.redhat.com/security/cve/CVE-2023-5764 - Vendor Advisory
References () https://access.redhat.com/errata/RHSA-2023:7773 - () https://access.redhat.com/errata/RHSA-2023:7773 - Vendor Advisory

13 Dec 2023, 10:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-12-12 22:15

Updated : 2024-09-16 17:16


NVD link : CVE-2023-5764

Mitre link : CVE-2023-5764

CVE.ORG link : CVE-2023-5764


JSON object : View

Products Affected

redhat

  • enterprise_linux
  • ansible
  • ansible_inside
  • ansible_automation_platform
  • ansible_developer

fedoraproject

  • extra_packages_for_enterprise_linux
  • fedora
CWE
NVD-CWE-Other CWE-1336

Improper Neutralization of Special Elements Used in a Template Engine